Yep, D is how you do it from the Falcon console. You just select the host under Host Management and use the Disable Detections option. Exclusion rules (A) won't fully silence everything-some detections could still slip by if not covered by the rule. Pretty confident on this one, but open to correction if there's a rare scenario I'm missing.
Q: 5
How do you disable all detections for a host?
Options
Discussion
Not sure about picking A here-exclusion rules don't cover everything, so you'd still get some alerts. D is the one that actually disables all detections for a host through Host Management. Let me know if you see it differently.
D , pretty much every practice exam and the official guide points to using Host Management for this. Anyone get a different result in live labs?
Seen similar on practice exams-D is what you pick.
Directly from the console, it’s D for this one.
A isn’t right here, D is. Disabling detections is a direct action in Host Management, it’s meant for times when you really need to suppress everything on a specific host. Pretty sure that’s the only supported way.
Its D. Host Management gives you that disable detections option right in the UI.
Be respectful. No spam.
Question 5 of 35